Text about the Post Quantum Cryptography Inquiry project by Paolo Cirio. 2026
The project Post Quantum Cryptography Inquiry is an independent research initiative exploring the future of cryptography.

The project inquires into the science of cryptography in the face of the quantum technology threat. This investigation aims to offer insights through video interviews with major experts in cryptography, quantum physics, mathematics, and cybersecurity. The interviews explore both the vulnerabilities and strengths of today’s cryptography, covering a wide spectrum of perspectives, including both skeptical and catastrophic ones. The ethics and policies surrounding post-quantum cryptography are examined within the efforts to develop and implement new forms of quantum-resistant cryptography, highlighting the importance of these initiatives.

This research was initiated and conducted by the Internet artist Paolo Cirio, in collaboration with mathematicians Kilton Hopkins, and Milanthi Sarukkali. We traveled across the United States and Europe to interview experts in major universities, research centers, and cyber-law organizations to inquire into the state of affairs of quantum technology. The potential breaking of the current common forms of encryption would compromise privacy in emailing and browsing, signatures and identity verification, hardware and critical infrastructures, financial transactions and crypto-currencies. With a particular focus on the mathematics behind encryption schemes, the interviews expand on the social, political, and economic impacts of the hypothetical collapse of modern cryptography in our heavily digital dependent global society.

As a survey, these interviews provide an overview of many perspectives, including differences in expectations, positions, and opinions. The project aims to provide educational and informative material for researchers, policymakers, journalists, and scholars. By investigating both opportunities and vulnerabilities that research in quantum science might bring, this project examines the potential dangers, solutions, and uncertainties around the future of cryptography. Through an in-depth inquiry across fields of expertise, the questions span from cybersecurity risks, quantum information science, cryptographic methods, to mathematical conjectures, and expands on ethics and policy concerning information technology.

There is a general acceptance that the world is moving toward Post-Quantum Cryptography. This advancement is marked by the efforts of institutions such as NIST, ENISA, and WEF, among others. However, uncertainty remains around when the new Post-Quantum Cryptography will become necessary, how robust it will be, and which will be the global standard. Concurrently, other unexpected discoveries in science and mathematics might change the current state of affairs and the need to accelerate the transition to Post-Quantum Cryptography. This independent research project looks at both potentials and limits of quantum technology in disrupting cryptography, aiming to offer a plurality of voices and considerations around cryptography and quantum information science.

This investigation aims to offer insights through video interviews with major experts in Cryptography, Quantum Physics, Mathematics, and Cybersecurity. The interviews explore both the vulnerabilities and strengths of today’s cryptography, covering a wide spectrum of perspectives, including both skeptical and catastrophic ones. The ethics and policies around Post-Quantum Cryptography are discussed with the efforts in developing and implementing new forms of quantum resistant cryptography, highlighting the importance of such initiatives.

More about the authors of the research
The authors of this research project operate as citizen scientists, and identify themselves as members of the public who voluntarily investigate self-initiated scientific questions without formal scientific credentials and outside scientific institutions. Paolo Cirio is a renowned Internet artist and digital-rights activist. Kilton Hopkins is a mathematician focused on cybersecurity and former director of the Level IoT Program at Northeastern University. Milanthi Sarukkali holds a PhD in Mathematics and is a consulting actuary focused on climate change.


Specifications

Quantum information science and technology could solve the mathematics of current cryptography, such as integer factoring and discrete-log problems, which are at the foundation of modern encryption schemes, directly undermining the security of most digital infrastructures. A number of protocols, algorithms, hardware, and services that rely on them could get broken unless they migrate to quantum-resistant alternatives and adopt crypto agility.

The following cryptographic schemes and related systems could get broken or weakened:

  • RSA (Rivest–Shamir–Adleman).
    Note: Security relies on integer factoring.

  • DSA (Digital Signature Algorithm).
    Note: Security relies on the discrete logarithm problem (finite-field / multiplicative group modulo a prime).

  • ECC / ECDSA (Elliptic-curve cryptography and Elliptic Curve Digital Signature Algorithm).
    Note: Security relies on the discrete logarithm problem in groups of points on elliptic curves.

  • HTTPS / TLS (transport security protocols).
    Note: Security relies on certificate-based authentication and underlying key-exchange algorithms.

  • Cryptocurrencies and Blockchain.
    Note: Those that rely on vulnerable primitives (signatures, hashing, or consensus elements relying on ECDSA/ECDH for transaction signatures and key management).

  • Diffie–Hellman (finite-field key exchange).
    Note: Security relies on the discrete-logarithm problem.

  • ElGamal (Taher ElGamal).
    Note: Encryption/signature schemes based on discrete logarithms.

  • Most VPN implementations.
    Note: Vulnerable when they rely on affected key-exchange or signature schemes.

  • Most Wi-Fi security protocols.
    Note: Protocols that depend on breakable primitives.

  • Secure boot and firmware verification chains and code-signing schemes (software update integrity).
    Note: Vulnerable when they use RSA/ECDSA signatures.

  • Hardware Security Modules (HSMs).
    Note: Protect keys physically but do not make weak primitives quantum-safe.

  • Smart cards.
    Note: Vulnerable when they rely on embedded asymmetric cryptography.

  • Many forms of two-factor authentication.
    Note: Those that rely on asymmetric keys or certificates (e.g., FIDO/WebAuthn hardware keys, some security keys).

  • Classical random number generators (RNGs).
    Note: Vulnerable when predictable or insufficient-entropy RNGs.

Most of the current public key infrastructure (PKI) could get broken, including digital certificates and certificate-based signatures that use RSA/ECC keys, which includes identity and authentication systems that depend on public-key signatures (e.g., SAML, JWTs with RSA/ECDSA), which could enable identity theft and forged certificates. PKI includes HTTPS/TLS, which protects web browsing, chat, and email applications. So much of the Internet’s encryption could be compromised. PKI-related cryptography also underpins government services, financial transactions, and business systems, which could be compromised. Ultimately, long-term confidentiality of archived data protected by vulnerable public-key algorithms could be retroactively decrypted via "collect now, decrypt later" tactics.

Development of quantum computers that become scalable and run error-corrected algorithms could break the mathematics underlying modern cryptography. Current experimental platforms—superconducting circuits, trapped ions, photonics, and others—are steadily increasing qubit counts and improving coherence and gate fidelity. When sufficiently many high-quality qubits are linked with robust error correction, they will be able to run algorithms at scales that threaten today’s cryptography. Other breakthroughs in quantum information science and technology could also accelerate these developments. For instance, theoretical research in quantum information could lead to solving the hard mathematical problems behind current encryption, which would then be breakable by classical computers. If the so-called Millennium problems of mathematics are solved, such as the Riemann hypothesis or the P vs NP problem, much encryption would become vulnerable and obsolete. Such mathematical conjectures are still open questions, and artificial intelligence or unconventional approaches might bring new mathematical discoveries.

The new Post-Quantum encryption and signature methods are built on mathematical problems believed to resist both classical and quantum attacks, such as lattice problems or hash functions, rather than factoring. However, transitioning will take years, given the effort required and the potential for roadblocks in deployment. The implementation of new Post-Quantum software and hardware would likely be coordinated through an international policy effort.

In January 2025, Joe Biden’s last act as president was to sign an executive order changing the deadline for government agencies to implement NIST’s algorithms from 2035 to “as soon as practicable.” In June 2026, Trump signed an executive order to anticipate the deadline to 2031. The European Commission released new guidelines in 2025 to accelerate the transition. Already in 2016, the US National Institute for Standards and Technology (NIST) launched a competition to develop quantum-proof encryption algorithms. This has been the most successful effort and the identified schemes are already implemented in critical applications and infrastructures. There have been other similar initiatives in Asia and Europe. However, these efforts are not internationally coordinated, often underfunded, and slowed down by the lack of sense of urgency and geopolitical conflicts.

Some international organizations that could lead to standards:

  • ENISA — European Union Agency for Cybersecurity.
  • NIST — US National Institute of Standards and Technology.
  • ITU — International Telecommunication Union.
  • IET — Institution of Engineering and Technology.
  • ISO — International Organization for Standardization.
  • IEEE — Institute of Electrical and Electronics Engineers.
  • COPA — Crypto Open Patent Alliance.
  • ETSI — European Telecommunications Standards Institute.
  • CEN/CENELEC — European Committee for Standardization / Electrotechnical.
  • SAC — Standardization Administration of China.
  • TC260 — National Technical Committee for Information Security Standardization China.

Some international organizations that could lead to policy for implementation:

  • WEF — World Economic Forum.
  • OECD — Organization for Economic Co-operation and Development.
  • European Commission — including the Council and European Parliament.
  • White House — including the U.S. Congress and the Executive Office of the President.
  • UNIDIR — United Nations Institute for Disarmament Research.



home | cv & bio | works | archive works | press | archive press | events | contact | top